Occasional Transfer
An 'occasional transfer' is a one-off or infrequent, non-routine transfer of personal data to a country outside the EU/EEA. The concept matters because certain exceptions that allow such transfers, for example where the transfer is necessary in relation to a contract or a legal claim, are generally understood to apply only where the transfer is occasional rather than regular or systematic. Whether a particular transfer qualifies as occasional depends on the facts and is subject to assessment.
In the context of Article 49 GDPR derogations for transfers of personal data to third countries, 'occasional' functions as an additional qualifying criterion that limits the availability of certain derogations. Recital 111 refers to a transfer being 'occasional and necessary' in relation to a contract or a legal claim, and regulatory guidance from the European Data Protection Board has generally favoured a strict interpretation under which only occasional (non-repetitive, non-systematic) processing operations fall within the relevant derogations. The term is not exhaustively defined in the operative text of the Regulation itself, so its application turns on the frequency, regularity, and structural nature of the transfer as assessed case by case; practitioners should note that regulator guidance and interpretation may evolve and should be verified against the current official text and EDPB materials. Note that 'occasional transaction' concepts appearing in anti-money-laundering or financial regulatory sources are distinct and should not be conflated with this GDPR data-transfer concept.
Why it matters
The concept of an 'occasional transfer' matters because it operates as a gatekeeping criterion for several of the Article 49 GDPR derogations that permit transfers of personal data to countries outside the EU/EEA in the absence of an adequacy decision or an appropriate safeguard such as Standard Contractual Clauses or Binding Corporate Rules. Recital 111 refers to a transfer being 'occasional and necessary' in relation to a contract or a legal claim, which is generally understood to mean that certain derogations are available only where a transfer is non-routine rather than regular or systematic. Organisations that treat these derogations as a general-purpose route for ongoing transfers may find that they have relied on a legal footing that does not, on assessment, apply to their circumstances.
The practical significance is heightened by the fact that European Data Protection Board guidance has generally favoured a strict interpretation, under which only occasional (non-repetitive, non-systematic) processing operations fall within the relevant derogations. This means that a transfer forming part of a stable, recurring data flow, for example, routine transfers embedded in day-to-day operations, will typically fall outside the derogation and require a different transfer mechanism. Mischaracterising a systematic flow as occasional can leave an organisation without a valid transfer tool for that activity.
Because 'occasional' is not exhaustively defined in the operative text of the Regulation, its application turns on the facts of each case and on regulator interpretation that may evolve over time. Practitioners should verify the current position against the official text and current EDPB materials, and should be careful not to conflate this GDPR concept with the separate notion of an 'occasional transaction' found in anti-money-laundering or financial regulatory sources, which addresses a different subject matter entirely.
Who it's relevant to
Inside Occasional Transfer
Common questions
Answers to the questions practitioners most commonly ask about Occasional Transfer.